cve

Tag

Cards List
#cve

Achieving NGINX Remote Code Execution via an 18-Year-Old Vulnerability

Lobsters Hottest · 2026-05-13 Cached

Researchers used an autonomous system to discover a critical heap buffer overflow vulnerability in NGINX's rewrite module (CVE-2026-42945), present since 2008, enabling remote code execution. Multiple CVEs were confirmed by NGINX.

0 favorites 0 likes
#cve

"six CVEs for serious security vulnerabilities in dnsmasq"

Lobsters Hottest · 2026-05-12 Cached

Six serious security vulnerabilities (CVEs) have been identified in dnsmasq, affecting most non-ancient versions. Simon Kelley has released version 2.92rel2 with patches and announced plans for an imminent 2.93 release to address these long-standing bugs.

0 favorites 0 likes
#cve

Non-determinism is an issue with patching CVEs

Hacker News Top · 2026-05-08 Cached

Article discusses how AI models like Claude Mythos, Big Sleep, and Microsoft Copilot are increasingly discovering CVEs, and how Nix/Flox provides a declarative package management solution that reduces CVE triage complexity from O(n) to O(u) through dependency set deduplication.

0 favorites 0 likes
#cve

CVE-2026-31431: Copy Fail

Lobsters Hottest · 2026-05-08 Cached

CVE-2026-31431 (Copy Fail) is a local privilege escalation vulnerability in the Linux kernel affecting all major distributions since 2017, allowing unprivileged users to gain root shell access through a deterministic 4-byte write to any readable file's page cache via the AF_ALG crypto subsystem.

0 favorites 0 likes
#cve

Vulnerability Garden: A growing list of named vulnerabilities, attack techniques and exploits

Lobsters Hottest · 2026-05-08 Cached

Vulnerability Garden is a curated list of named vulnerabilities, attack techniques, and exploits, providing references and dates for each entry.

0 favorites 0 likes
#cve

The React2Shell Story

Hacker News Top · 2026-05-08 Cached

Security researcher Lachlan discovered and reported a critical remote code execution vulnerability dubbed "React2Shell" in React's Server Components protocol to Meta on November 30, 2025. Meta released a fix and public advisory (CVE-2025-55182) on December 3, urging developers to update immediately as the vulnerability affected millions of websites built with React/Next.js.

0 favorites 0 likes
#cve

Copy Fail 2: Electric Boogaloo

Lobsters Hottest · 2026-05-08 Cached

Copy Fail 2 is a proof-of-concept exploit for an unprivileged Linux Local Privilege Escalation (LPE) vulnerability in the kernel's xfrm subsystem, allowing attackers to gain root access on modern distributions.

0 favorites 0 likes
#cve

LemmaScript: A Verification Toolchain for TypeScript via Dafny

Lobsters Hottest · 2026-04-22 Cached

LemmaScript is a new toolchain that compiles TypeScript to Dafny for formal verification without altering the runtime, demonstrated by proving a CVE fix in the Hono framework.

0 favorites 0 likes
← Previous
← Back to home

Submit Feedback